Privacy Policy
Last updated: 30 June 2026On this page
- Who we are
- What we collect
- How we use your information
- Legal bases for processing
- Service providers & sub-processors
- AI processing of your content
- Social auto-posting
- Marketing email & newsletter
- Data retention
- Your rights
- California privacy rights (CCPA/CPRA)
- Security
- International transfers
- Children
- Changes to this policy
- Contact us
Last updated: . This Privacy Policy explains how VEUGA ("VEUGA", "we", "us"), operated by Maukx LLC, collects, uses, and protects your information when you use our website and services (the "Service"). We've written it to be readable, not just compliant.
1. Who we are
VEUGA is an AI marketing platform operated by Maukx LLC, a Wyoming limited liability company, based in the United States. For the purposes of the UK/EU General Data Protection Regulation (GDPR), Maukx LLC is the data controller for personal data processed through the Service.
For any privacy question, or to exercise your rights, contact [email protected].
2. What we collect
We collect only what we need to run the Service.
Information you give us
- Account information — your email address and authentication details, handled by our authentication provider (see section 5). If you sign in with Google or GitHub, we receive your email address and basic profile information from them.
- Content you submit — the website URLs you run through VEUGA, and any text you edit or store within the Service.
- Workspace information — the names you give your workspaces and the assets generated within them.
- Newsletter signups — your email address, if you subscribe.
- Communications — anything you send us by email or through a contact form.
- Automation settings — if you connect social auto-posting, the webhook URL you provide (see section 7).
Information collected automatically
- Usage data — the runs you start, their status, and timestamps, so we can operate the Service, enforce plan limits, and diagnose failures.
- Technical data — IP address, browser type, and device information, collected in server logs by our infrastructure providers for security and reliability.
- Cookies and similar technologies — see our Cookie Policy.
What we do not collect
- We never see or store your social media passwords. If you use auto-posting, your social account credentials live in your own third-party automation account, not with us.
- We do not collect special category data (health, biometrics, political opinions, etc.), and you should not submit it to the Service.
- We do not store payment card details. If and when paid plans are enabled, card data is handled entirely by our payment processor.
3. How we use your information
- To provide the Service — running your URL through our AI agents and returning the generated assets.
- To authenticate you and keep your account secure.
- To enforce plan limits (for example, how many runs you may start each month).
- To communicate with you about the Service — important account, security, or service notices.
- To send marketing email only where you have subscribed (see section 8).
- To diagnose failures, prevent abuse, and improve reliability.
- To comply with legal obligations.
We do not sell your personal data, and we do not share it with advertisers.
4. Legal bases for processing
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract — to provide the Service you signed up for.
- Legitimate interests — to secure the Service, prevent abuse, and improve it, balanced against your rights.
- Consent — for marketing email and non-essential cookies. You may withdraw consent at any time.
- Legal obligation — where we must retain or disclose information by law.
5. Service providers & sub-processors
We use a small number of trusted providers to run the Service. Each processes data only as needed to perform their function:
- Clerk — authentication and account management (stores your email and login credentials).
- Supabase — database hosting (stores your runs, generated assets, workspaces, and settings).
- Amazon Web Services (AWS) — hosting, compute, and email delivery (Amazon SES) for transactional and newsletter email.
- Cloudflare — content delivery and security in front of our website.
- Anthropic — the AI provider that powers our agents. Content you submit (your URL and the derived text) is sent to Anthropic's API to generate your assets. See section 6.
- Stripe — payment processing, if and when paid plans are enabled. Stripe handles card data directly; we never receive your full card details.
We may add or change providers as the Service evolves; we will update this policy when we do. If you connect a third-party automation tool for auto-posting (for example Make.com or n8n), that tool is your provider, governed by its own privacy policy — not ours.
6. AI processing of your content
VEUGA is an AI product, so it's important you understand what happens to what you submit:
- When you start a run, we fetch the public content of the URL you provide and send relevant text to our AI provider to generate your marketing assets.
- The assets returned are stored in your account so you can view, edit and export them.
- We do not use your content to train AI models. Your business content and generated assets are yours.
- AI output can be inaccurate or incomplete. It is a first draft, not professional advice. You are responsible for reviewing anything before you publish it. See our Terms of Service.
- Do not submit confidential information, personal data about others, or anything you are not permitted to share.
7. Social auto-posting
If you enable auto-posting, VEUGA sends your scheduled posts to a webhook URL that you provide, belonging to an automation account you control (such as Make.com or n8n). That automation then publishes to your social accounts.
- We store only the webhook URL and your on/off preference.
- We never receive, store, or have access to your social media passwords or access tokens. Those remain in your own automation account.
- Once a post leaves VEUGA for your webhook, it is handled by your automation provider and the relevant social platform, each under their own terms and privacy policies.
8. Marketing email & newsletter
- We send marketing email only to people who have subscribed to our newsletter. We do not buy, rent, or scrape email lists.
- Every marketing email contains a clear, working unsubscribe link. Unsubscribing takes effect promptly, and we will not send you further marketing email.
- Every marketing email identifies us as the sender, uses an accurate subject line, and includes a valid postal address, as required by the US CAN-SPAM Act.
- We may still send you essential service messages (for example, security, billing, or account notices) — these are transactional, not marketing, and cannot be unsubscribed from while you hold an account.
- Newsletter email is delivered via Amazon SES.
If you are in the UK or EU, we rely on your consent for marketing email, and you may withdraw it at any time by unsubscribing.
9. Data retention
- Account data — retained while your account is active.
- Runs and generated assets — retained while your account is active, so you can access your work.
- Newsletter subscriptions — retained until you unsubscribe.
- Logs — retained for a limited period for security and diagnostics.
If you delete your account, we delete your runs, workspaces, generated assets and settings. Some information may persist briefly in backups or where we are legally required to retain it.
10. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data ("right to erasure").
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent at any time (for example, unsubscribe from marketing).
- Complain to a supervisory authority in your jurisdiction.
To exercise any of these, email [email protected]. We will respond within the timeframe required by applicable law. We do not discriminate against you for exercising your rights.
11. California privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you specific rights regarding your personal information.
What we collect and why
The categories of personal information we collect are set out in section 2 above — principally identifiers (such as your email address), internet activity (such as usage of the Service), and the content you submit. We collect it for the business purposes described in section 3.
We do not sell or share your personal information
We do not sell your personal information, and we do not "share" it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA. We have not done so in the preceding 12 months. Because we do not sell or share, we do not offer a "Do Not Sell or Share My Personal Information" link — there is nothing to opt out of.
Your California rights
- Right to know — the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties we disclose it to.
- Right to delete — request deletion of the personal information we hold about you, subject to legal exceptions.
- Right to correct — request correction of inaccurate personal information.
- Right to limit use of sensitive personal information. We do not collect sensitive personal information as defined by the CPRA.
- Right to non-discrimination — we will not deny you service, charge you a different price, or provide a lesser quality of service because you exercised a privacy right.
How to exercise them
Email [email protected] from the address associated with your account, stating which right you wish to exercise. We will verify your identity before acting on your request, and will respond within the timeframes required by law (generally 45 days, extendable where permitted). You may use an authorised agent to make a request on your behalf, subject to verification.
12. Security
- Your runs and assets are private to your account, enforced at the database level (row-level security) — not merely hidden in the interface.
- Data is encrypted in transit (HTTPS/TLS) and at rest by our infrastructure providers.
- Access to production systems is limited to those who need it.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities where required by law.
13. International transfers
Maukx LLC is based in the United States, and our providers operate in the United States, the European Union and elsewhere. If you are located outside the United States — for example in the UK or EU — your personal data will be transferred to, stored in, and processed in the United States, which may not provide the same level of data protection as your home jurisdiction.
Where required for transfers out of the UK/EEA, we rely on appropriate safeguards such as the Standard Contractual Clauses (and the UK Addendum where applicable), which our providers make available. You may request a copy of the relevant safeguards by emailing [email protected].
By using the Service, you understand that your information will be processed in the United States.
14. Children
The Service is not intended for anyone under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.
15. Changes to this policy
We may update this policy as the Service evolves or the law changes. We will update the "last updated" date above, and for material changes we will make reasonable efforts to notify you — for example, by email or a notice in the Service.
16. Contact us
Questions, requests, or complaints about privacy:
Maukx LLC
[REGISTERED ADDRESS — ]
Wyoming, United States
Email: [email protected]